From Smartphone to Secure Payment Terminal: How SoftPOS and PCI MPoC Are Redefining Payment…
From Smartphone to Secure Payment Terminal: How SoftPOS and PCI MPoC Are Redefining Payment Acceptance

What if a merchant no longer needed a traditional physical payment terminal to accept a contactless transaction?
That is precisely the idea behind SoftPOS.
SoftPOS: When the Smartphone Becomes the Payment Terminal
SoftPOS — short for Software Point of Sale — turns a smartphone or tablet equipped with NFC into a payment acceptance device.
The concept is straightforward.
A merchant installs a SoftPOS application on a compatible device. The customer can then tap a contactless card, smartphone, or smartwatch against the merchant's device, and the transaction can be initiated directly from the phone.
From the outside, it looks remarkably simple.
Underneath, however, SoftPOS involves a sophisticated security architecture.
The application and its surrounding environment must address several critical areas, including:
- NFC communication with the payment card or digital wallet;
- EMV data and cryptograms generated during the transaction;
- Transaction authentication and security;
- Protection of sensitive payment data;
- Communication with the acquirer and the broader payment ecosystem;
- Security requirements applicable to mobile payment acceptance.
This is what makes SoftPOS much more than simply "installing a payment application" on a smartphone.
The real challenge is not making the phone accept a tap.
The challenge is ensuring that a consumer-grade device can provide a security environment compatible with the requirements of the payment industry.
And this is where PCI security standards become particularly important.
From Dedicated Hardware to COTS Devices
Traditionally, payment acceptance has relied on dedicated hardware: the physical POS terminal, or TPE.
SoftPOS changes that model by using a COTS device — Commercial Off-The-Shelf — such as a smartphone or tablet.
The evolution can therefore be viewed as:
Physical POS terminal → Mobile POS → Smartphone as a payment terminal
The business appeal is significant.
A small merchant, independent professional, delivery driver, or mobile business may potentially need nothing more than a smartphone to accept payments.
This can reduce dependence on dedicated payment hardware and potentially simplify deployment and operations.
But moving payment acceptance onto a general-purpose device introduces a fundamental question:
How do you protect payment credentials and transaction data when the payment terminal itself is a device designed for everyday consumer use?
This question becomes particularly critical when a transaction involves a PIN or other sensitive payment data.
That is where the PCI COTS standards enter the picture.
PCI SPoC: Protecting PIN Entry on a Smartphone
One of the first important pieces of this evolution was PCI SPoC — Software-based PIN Entry on COTS.
SPoC addresses scenarios in which the cardholder enters their PIN directly on a COTS device, such as a smartphone or tablet.
The security challenge is obvious: the PIN is one of the most sensitive pieces of information in a payment transaction.
SPoC therefore establishes security mechanisms around the capture and protection of the PIN, including:
- secure PIN capture;
- encryption of the PIN;
- mechanisms for attestation;
- monitoring mechanisms designed to protect this critical data.
The objective is to allow a software-based payment environment to handle PIN entry while maintaining appropriate security controls around the most sensitive stage of the transaction.
PCI CPoC: Bringing Contactless Payments to COTS
SoftPOS also created another important use case: contactless acceptance without an external payment reader.
This is the purpose of PCI CPoC — Contactless Payments on COTS.
CPoC targets contactless payment transactions where the smartphone or tablet uses its native NFC capability to accept the transaction.
In other words, the merchant does not necessarily need to connect a separate contactless reader to the smartphone.
The COTS device itself becomes the contactless acceptance interface.
A customer can simply tap a contactless card, smartphone, or wearable against the merchant's NFC-enabled device.
This is one of the fundamental ideas behind the SoftPOS model: leveraging capabilities that already exist inside modern smartphones rather than reproducing the functionality of a traditional payment terminal through dedicated hardware.
PCI MPoC: Bringing the Security Model Together
The evolution does not stop with SPoC and CPoC.
PCI MPoC — Mobile Payments on COTS — takes a broader and more flexible approach.
Rather than focusing on only one specific acceptance scenario, MPoC provides a more flexible and modular architecture capable of supporting different payment acceptance scenarios.
This is particularly important because modern payment acceptance does not necessarily fit into a single model.
A merchant may need to support contactless payments. Another environment may require PIN entry. In some scenarios, both capabilities may need to coexist on the same COTS device.
MPoC is designed to address these different scenarios within a more unified security architecture.
This makes it particularly relevant to the future of SoftPOS.
Instead of treating PIN-based acceptance and contactless acceptance as completely separate worlds, MPoC provides a framework that can accommodate multiple mobile payment acceptance use cases.
Why This Matters for the Payment Industry
The implications go far beyond the smartphone itself.
For banks, acquirers, PSPs, payment solution providers, and merchants, the opportunity is significant:
How can we reduce dependence on dedicated payment hardware while maintaining a level of security that is controlled, assessed, and aligned with payment-industry requirements?
That is the real value proposition behind the combination of SoftPOS and PCI security standards.
The smartphone is not automatically a secure payment terminal simply because it has NFC.
The security comes from the architecture, software, cryptographic protections, secure execution environments, monitoring, attestation mechanisms, and compliance framework surrounding the payment application.
Technologies such as tokenization, secure environments within the smartphone, and industry security standards therefore play an essential role in making the model viable.
The Transition from SPoC and CPoC to MPoC
There is also an important evolution to understand.
As of 2026, PCI SPoC and PCI CPoC have entered an official retirement phase, with their evolution now being carried forward through PCI MPoC.
This is more than a change in terminology.
It reflects the industry's move toward a more unified and modular approach to mobile payment acceptance on COTS devices.
The direction is clear: rather than building separate security models around individual use cases, the industry is moving toward an architecture capable of supporting multiple payment acceptance scenarios while maintaining rigorous security controls.
The Bigger Picture
SoftPOS represents an important evolution in payment acceptance.
The smartphone is no longer merely the device used by the consumer to make a payment.
It can also become the device used by the merchant to accept that payment.
That shift has technical, operational, and economic consequences.
For merchants, it can mean less dependence on dedicated hardware.
For banks, acquirers, PSPs, and payment solution providers, it opens the door to more flexible deployment models.
But for the payment industry as a whole, the fundamental challenge remains security.
Turning a COTS smartphone into a payment terminal is not simply a software-development exercise. It requires a carefully designed security architecture capable of protecting payment data and sensitive credentials within an environment that was never originally designed to be a payment terminal.
And that is precisely why the evolution from SPoC and CPoC toward MPoC is so important.
My Take
In my view, the most interesting aspect of SoftPOS is not simply that a smartphone can replace a traditional POS terminal.
It is that SoftPOS can change the economic and operational model of payment acceptance itself.
The terminal is no longer necessarily a dedicated piece of hardware.
It can become a secure software-defined payment environment running on a device that merchants already carry every day.
That is a much bigger transformation than simply replacing a card reader with a smartphone.
메타데이터
- post_id
- 4acc6c5cbc6a
- slug
- from-smartphone-to-secure-payment-terminal-how-softpos-and-pci-mpoc-are-redefining-payment-4acc6c5cbc6a
- url
- https://medium.com/@olwanmohammad/from-smartphone-to-secure-payment-terminal-how-softpos-and-pci-mpoc-are-redefining-payment-4acc6c5cbc6a
- canonical_url
- https://medium.com/@olwanmohammad/from-smartphone-to-secure-payment-terminal-how-softpos-and-pci-mpoc-are-redefining-payment-4acc6c5cbc6a
- author_url
- https://medium.com/@olwanmohammad
- status
- ok
- fetched_at
- 2026-08-16 19:24:42